aboutcode-org / aboutcode-org/scancode-toolkit
Support npm dependencies with "weird" versions
未关闭
bug
dependencies
package scan
package-formats
- 主要语言
- Python
- 星标
- 2.6k
- 派生
- 791
- 平均合并
- 1 天 12 小时
- 30 天内合并 PR
- 5
描述
Per https://docs.npmjs.com/cli/v7/configuring-npm/package-json#dependencies the version of a dependency can be various things:
- URLs as Dependencies: "http://asdf.com/asdf.tar.gz",
- Git URLs as Dependencies: See https://docs.npmjs.com/cli/v7/configuring-npm/package-json#git-urls-as-dependencies ... this is using a VCS_URL-os-SPDX and pip-like syntax
- GitHub URLs: user/repo#feature\/branch
- Local Paths: "bar": "file:../foo/bar" ....
These versions end up in the package-lock.json too and they are not really versions.
We should instead treat them as requirements and not as concrete versions.
This is also impacting ScanCode.io BTW
贡献指南
评估
这个 Issue 还没有评估数据。